Also known as: Personal Panda, UNC4841, Deputy Dog, Royal Ransomware, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code
Asnarök first emerged in early 2020 with a Trojan that specifically infects firewall appliances and escalates privileges by exploiting the command injection flaw CVE‑2020‑12271. Their early operations involved deploying lightweight web shells that communicate over HTTP without reaching out to external C2 servers, subsequently harvesting local user account data using custom scripts such as IC.sh. In later phases, Asnarök expanded their operational footprint by creating anonymous cloud accounts—across Dropbox, MEGA, OneDrive, and AWS S3—to host malware payloads, exfiltrate stolen data, and establish footholds inside victim networks. A hallmark of Asnarök is the systematic hijacking of legitimate Windows service binaries; by replacing executables in system directories they elevate themselves to SYSTEM level, enabling persistence and stealth. They also backdoor container images within AWS, GCP, Azure, or Docker registries, thereby bypassing traditional network segmentation and embedding persistence directly into cloud workloads. Beyond lateral movement, the actor actively targets multi‑factor authentication mechanisms using credential harvesting or interception techniques, often accompanied by spoofed User‑Agent strings to masquerade as legitimate traffic. Their tactics blend stealthy exfiltration with opportunistic ransomware-like impacts, associating their activity with the BLINDINGCAN malware family in recent reports, while still maintaining a distinct custom Trojan arsenal under the Asnarök name.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Asnarök is a financially motivated threat actor that employs a custom Trojan to target firewall devices and exploits public‑facing software vulnerabilities for initial access. They build extensive persistence through cloud account abuse, Windows service hijacking, and container image backdoors while exfiltrating data via popular cloud storage services. The group demonstrates advanced tactics such as MFA bypass, user‑agent spoofing, and lateral movement across a broad set of sectors in multiple regions.
Goals & Targeting
Asnarök’s primary strategic objective is monetary gain, achieved through data theft, credential exploitation, and potential ransom or extortion. The actor deliberately selects high‑profile sectors—including finance, defense, government, healthcare, telecoms, critical infrastructure, and media—across a spectrum of countries such as China, Russia, India, Ukraine, the UK, Germany, North Korea, Iran, Pakistan, Belarus, Poland, Taiwan, Canada, and Australia. By capitalizing on publicly disclosed vulnerabilities, cloud misconfigurations, and MFA weaknesses, Asnarök maximizes its reach while maintaining low technical footprints through user‑agent spoofing and internal C2 avoidance.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The actor demonstrates a patient‑to‑opportunistic campaign rhythm, leveraging newly disclosed public vulnerabilities and known software weaknesses to plant backdoors. Asnarök’s operations often begin with small footholds—such as compromised firewall devices or vulnerable remote services—and then expand via cloud account hijacking and container image tampering. Victims span multiple industries and countries; the group prefers environments where MFA is enabled but can be subverted, and where remote administration tools are exposed to the internet. Notable operations include a 2024 report linking Asnarök to the BLINDINGCAN family, alongside earlier incidents involving custom Trojan deployments in critical infrastructure networks.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is derived from a combination of publicly available incident reports, open‑source intelligence, and observed technical behaviors. Core tactics and techniques—such as CVE‑2020‑12271 exploitation, cloud account abuse, and Windows service hijacking—are well documented, providing moderate confidence in these aspects. However, details regarding the actor’s internal command structure, full toolchain, precise operational timeline, and definitive attribution remain incomplete due to limited source material.
No campaigns linked yet.
No observed data linked yet.
42
Techniques
41
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics